Description
WordPress Plugin BCS BatchLine Book Importer is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently import/update arbitrary products. WordPress Plugin BCS BatchLine Book Importer version 1.5.7 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.5.8 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:23B76562-D2AF-4753-BCE4-002921F3378E
https://plugins.svn.wordpress.org/bcs-bertline-book-importer/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin ArcadePress 'upload.php' Arbitrary File Upload (0.65)
RubyGems Deserialization of Untrusted Data Vulnerability (CVE-2018-1000074)
phpMyAdmin Resource Management Errors Vulnerability (CVE-2014-9218)
GlassFish Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-3239)